Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
131431 6.5 警告
Network
FusionAuth fusionauth-samlv2 FusionAuth fusionauth-samlv2 における XML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2021-27736 2021-12-22 17:58 2021-02-7 Show GitHub Exploit DB Packet Storm
131432 7.8 重要
Local
Matthias Wandel jhead jhead における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2021-3496 2021-12-22 17:58 2021-04-13 Show GitHub Exploit DB Packet Storm
131433 8.1 重要
Network
チェック・ポイント・ソフトウェア・テクノロジーズ Identity Agent Check Point Identity Agent における脆弱性 CWE-noinfo
情報不足
CVE-2021-30356 2021-12-22 17:58 2021-04-22 Show GitHub Exploit DB Packet Storm
131434 7.5 重要
Network
ABUS Secvest Wireless Alarm System FUAA50000 ファームウェア ABUS Secvest wireless alarm system FUAA50000 における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2020-28973 2021-12-22 17:58 2020-11-20 Show GitHub Exploit DB Packet Storm
131435 6.5 警告
Network
Eclipse Foundation Eclipse OpenJ9 Eclipse Openj9 におけるリソースの初期化の不備に関する脆弱性 CWE-909
リソースの初期化の不備
CVE-2021-28167 2021-12-22 17:58 2021-03-3 Show GitHub Exploit DB Packet Storm
131436 9.8 緊急
Network
pupnp project pupnp pupnp における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2021-29462 2021-12-22 17:58 2021-04-20 Show GitHub Exploit DB Packet Storm
131437 9.6 緊急
Network
TIBCO Software TIBCO Runtime Agent 複数の TIBCO 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2021-28827 2021-12-22 17:58 2021-04-20 Show GitHub Exploit DB Packet Storm
131438 6.7 警告
Local
- Dell PowerScale OneFS における OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2021-21526 2021-12-22 17:58 2021-04-12 Show GitHub Exploit DB Packet Storm
131439 8.8 重要
Network
Debian
Fedora Project
Google
Debian GNU/Linux
Google Chrome
Fedora
Google Chrome におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2021-21225 2021-12-22 17:57 2021-04-20 Show GitHub Exploit DB Packet Storm
131440 8.8 重要
Network
Debian
Fedora Project
Google
Debian GNU/Linux
Google Chrome
Fedora
Google Chrome における型の取り違えに関する脆弱性 CWE-843
型の取り違え
CVE-2021-21224 2021-12-22 17:57 2021-04-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
531 5.4 MEDIUM
Network
- - Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authentica… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-56774 2026-06-26 07:17 2026-06-26 Show GitHub Exploit DB Packet Storm
532 7.5 HIGH
Network
- - Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with… New CWE-494
 Download of Code Without Integrity Check
CVE-2021-47987 2026-06-26 07:16 2026-06-26 Show GitHub Exploit DB Packet Storm
533 8.8 HIGH
Network
- - Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth … New CWE-862
 Missing Authorization
CVE-2026-56767 2026-06-26 06:16 2026-06-26 Show GitHub Exploit DB Packet Storm
534 - - - Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST /-/api/sanitize_ipynb allows arbitrary data: URIs without proper restrictions,… New CWE-80
Basic XSS
CVE-2026-52816 2026-06-26 06:16 2026-06-25 Show GitHub Exploit DB Packet Storm
535 3.5 LOW
Network
- - Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In internal/markup/markup.go, … New CWE-1336
 Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-52796 2026-06-26 06:16 2026-06-25 Show GitHub Exploit DB Packet Storm
536 4.9 MEDIUM
Network
- - Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or wiki page can trigger a denial of service condition in which the … New CWE-20
 Improper Input Validation 
CVE-2025-64719 2026-06-26 06:16 2026-06-25 Show GitHub Exploit DB Packet Storm
537 7.1 HIGH
Network
- - Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by expl… New CWE-862
 Missing Authorization
CVE-2026-57520 2026-06-26 05:22 2026-06-26 Show GitHub Exploit DB Packet Storm
538 5.5 MEDIUM
Local
- - Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit New CWE-88
Argument Injection
CVE-2026-11968 2026-06-26 05:21 2026-06-24 Show GitHub Exploit DB Packet Storm
539 8.0 HIGH
Network
- - py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, w… New CWE-59
Link Following
CVE-2026-23879 2026-06-26 05:21 2026-06-25 Show GitHub Exploit DB Packet Storm
540 7.2 HIGH
Network
- - 3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by … New CWE-73
 External Control of File Name or Path
CVE-2026-55477 2026-06-26 05:21 2026-06-26 Show GitHub Exploit DB Packet Storm